
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 1
Supply Chain Security KCSA Practice Questions (Page 4)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
13concepts
16%of the exam
Questions 16–20
- 16
A Node.js application build broke because a transitive dependency was updated to a version with a known vulnerability. The team wants to ensure that builds are reproducible and that dependency versions are locked to known-good versions. Which practice should they adopt?
Select an answer first - 17
What is the primary goal of supply chain security in the Kubernetes and cloud native ecosystem?
Select an answer first - 18
Why is supply chain security particularly important in the Kubernetes and cloud native ecosystem?
Select an answer first - 19
What is the recommended way to handle secrets (e.g., API keys, passwords) in a CI/CD pipeline?
Select an answer first - 20
A developer is writing a web application that accepts user input and displays it on a page. To prevent cross-site scripting (XSS) attacks, which coding practice should the developer follow?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.